Cesanta Mongoose MQTT Message Parsing Heap Overflow
CVE-2023-2905
What is CVE-2023-2905?
The Mongoose web server, developed by Cesanta, exhibits a heap-based buffer overflow vulnerability in version 7.10 due to inadequate validation of the length of parsed MQTT_CMD_PUBLISH messages with variable-length headers. This flaw, found in the default configuration, could potentially allow attackers to exploit system memory. Users of Mongoose versions prior to 7.10 are not affected, and the issue is addressed in version 7.11. It's crucial for administrators using affected versions to upgrade to ensure system integrity and security.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Mongoose 7.10
Mongoose 7.11
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
